Data Processing Agreement (DPA)
Effective date: 15 July 2026
This Data Processing Agreement (“DPA”) applies where you use 8legs to process personal data of third parties (for example your employees, customers, or other individuals) in the course of your business. In that case you act as the “Controller” and UAB Gildium acts as your “Processor” under Article 28 of the EU General Data Protection Regulation (GDPR). This DPA forms part of, and is incorporated by reference into, our Terms of Service (the “Principal Agreement”).
How this DPA fits with our other terms
- Our Privacy Policy governs data for which we are the controller — for example your account details and how we run the service.
- This DPA governs data for which you are the controller and we are your processor — the third-party personal data you choose to submit through 8legs.
- The Terms of Service govern the overall relationship. If this DPA conflicts with the Terms on the subject of data protection, this DPA prevails.
If you are a consumer using 8legs for personal purposes, you are not a controller and this DPA does not apply to you — only the Terms and Privacy Policy do.
1. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Sub-processor" and "Supervisory Authority" have the meanings given in the GDPR. "Applicable Data Protection Law" means the GDPR, the UK GDPR, and any other data-protection or privacy law applicable to the processing.
2. Roles and scope
You (Controller) determine the purposes and means of the processing. We (Processor) process Personal Data only on your behalf to provide the service described in the Principal Agreement. The details of the processing are set out in Annex A.
3. Our obligations as Processor
We shall:
- Process only on your documented instructions — including on transfers — unless required by law, in which case we will inform you first unless that law prohibits it. Your use of the service, and this DPA, constitute your initial documented instructions.
- Confidentiality — ensure that personnel authorised to process the Personal Data are bound by confidentiality obligations.
- Security — implement appropriate technical and organisational measures under Article 32 GDPR, as described in Annex B.
- Assist you — taking into account the nature of the processing, assist you by appropriate measures in responding to Data Subject requests (access, rectification, erasure, restriction, portability, objection).
- Assist with compliance — assist you in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to us.
- Deletion or return — at your choice, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless law requires storage.
- Demonstrate compliance — make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate (subject to reasonable notice, confidentiality, and no more than once per year unless required by a Supervisory Authority).
- Notify unlawful instructions — immediately inform you if, in our opinion, an instruction infringes Applicable Data Protection Law.
4. Personal data breach
We shall notify you without undue delay after becoming aware of a Personal Data breach affecting your data, and provide information reasonably available to help you meet your own breach-notification obligations to Supervisory Authorities and Data Subjects.
5. Sub-processors
You provide general authorisation for us to engage the Sub-processors listed in Annex C to help deliver the service. We will:
- impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA (flow-down), by written contract;
- remain fully liable to you for the performance of each Sub-processor's obligations; and
- give you reasonable prior notice of any intended addition or replacement of a Sub-processor, so you have the opportunity to object on reasonable data-protection grounds.
6. International transfers
Some Sub-processors are located outside the European Economic Area (including the United States). Where we transfer your Personal Data outside the EEA/UK, we do so on the basis of an adequacy decision, the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), or another valid transfer mechanism, together with any supplementary measures required. The Standard Contractual Clauses are incorporated into this DPA by reference where they apply.
7. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA limits either party's liability to Data Subjects or Supervisory Authorities under Applicable Data Protection Law.
8. Term and termination
This DPA takes effect when you accept the Principal Agreement (or begin using 8legs as a Controller) and continues until all processing of your Personal Data by us has ceased and the data has been deleted or returned in accordance with clause 3.
9. Governing law
This DPA is governed by the laws of Lithuania, without prejudice to any mandatory provisions of Applicable Data Protection Law.
Annex A — Details of processing
- Subject matter: provision of the 8legs multi-model AI audit service.
- Duration: for the term of the Principal Agreement.
- Nature and purpose: receiving questions and related content submitted by the Controller, transmitting them to third-party AI models, and storing and displaying the results within the Controller's account.
- Types of Personal Data: any personal data the Controller chooses to include in submitted questions, follow-ups, and account information (Controllers are advised not to submit special-category data).
- Categories of Data Subjects: as determined by the Controller (e.g. the Controller's staff, customers, or other individuals referenced in submitted content).
Annex B — Security measures (Article 32)
- Encryption of data in transit (HTTPS/TLS) and encryption at rest on our cloud infrastructure.
- Access controls and authentication; data segregated per user account.
- Use of reputable cloud providers (Google Cloud / Firebase) with recognised security certifications.
- Least-privilege access for personnel and confidentiality obligations.
- Logging, monitoring, and a process to respond to security incidents.
- Regular review of measures appropriate to the risk.
Annex C — Approved Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Google (Firebase Auth, Firestore, App Hosting) | Sign-in, account storage, session/audit storage, hosting | USA / EU |
| Stripe | Payment processing and subscription billing | USA / EU / global |
| OpenAI | AI model responses — called directly | USA |
| Anthropic | AI model responses — called directly | USA |
| xAI | AI model responses (Grok) — called directly | USA |
| Google (Gemini API) | AI model responses (Gemini) — called directly | USA |
| Replicate | Hosts and runs the remaining AI models (Llama, DeepSeek, Kimi, Qwen) | USA |
Contact
To request a signed copy of this DPA, raise a Sub-processor objection, or exercise audit rights, contact support@8legs.app.